kevmap

TechniquesT1040 › AN0878

AN0878 Analytic 0878

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects creation of traffic mirroring sessions (e.g., AWS VPC Traffic Mirroring, Azure vTAP) that redirect traffic from critical assets to other virtual instances, often followed by file creation or session establishment.</p>
Detects
T1040 Network Sniffing
Part of
DET0314 Detection Strategy for Network Sniffing Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailCreateTrafficMirrorSession / ModifyTrafficMirrorTargetDC0069 Cloud Service Modification

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MirrorSourceListIdentify VMs or containers where mirror sessions are abnormal or unexpected.
TargetIAMRoleMonitor whether mirror target roles match administrative expectations.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-32030ASUS RoutersMapped
CVE-2022-1040Sophos FirewallMapped